Authdog
Log In

Log Streaming · Setup

Set up Sumo Logic

Sumo Logic receives the Authdog audit stream at an HTTP Source.

Lidar still detects and triages inside Authdog. This channel copies the same events to the collector URL you already search. Configuration belongs to one environment.

Create the channel

In the Authdog console:

  1. Select the project and environment.
  2. Open Notifications > Channels.
  3. Select Add Channel.
  4. Set Channel Name and Channel Type to Sumo Logic.
  5. Paste the HTTP Source URL into Collector URL. The URL is the credential. Treat it as a secret.
  6. Optionally set Source Category, Source Name, and Source Host. These override the X-Sumo-* metadata on each delivery.
  7. Choose the event triggers. Leave the event list empty to drain every event. Build a narrower list from the event catalog.
  8. Save, then send a test delivery.

The collector URL is stored as a secret. Later edits show it as redacted. Select Change only when you are replacing it.

What lands in Sumo Logic

Deliveries authenticate with the collector URL itself, not the X-Authdog-Signature header used by generic webhooks. A 2xx from Sumo Logic is success. Failures retry with exponential backoff, starting at 60 seconds, for at most five attempts. Inspect delivery records if a test does not appear.

This is log intake, not a Lidar detector. Signals stay in the console under Lidar.

Test it

  1. Trigger a sign-in in the same environment.
  2. Search the HTTP Source for the category or source name you set.
  3. Confirm a failed destination shows up in delivery records, then recovers after Sumo Logic accepts the retry.

Repeat the channel in production with a production HTTP Source. Channels do not copy between environments.

Read To learn how to
Events and webhooks Channel fields, retries, and the event catalog
Datadog The same stream, sent to Datadog
Marketplace The listing for this integration